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Security of the Ekert protocol is proven against individual attacks where an eavesdropper is al- 
lowed to share any density matrix with the two communicating parties. The density matrix spans 
all of the photon number states of both receivers, as well as a probe state of arbitrary dimension- 
ality belonging to the eavesdropper. Using this general eavesdropping strategy, we show that the 
Shannon information on the final key, after error correction and privacy amplification, can be made 
, exponentially small. This is done by finding a bound on the eavesdropper's average collision proba- 

bility. We find that the average collision probability for the Ekert protocol is the same as that of the 
BB84 protocol for single photons, indicating that there is no analog in the Ekert protocol to pira- 
cy ■ ton splitting attacks. We then compare the communication rate of both protocols as a function of 
' distance, and show that the Ekert protocol has potential for much longer communication distances, 

■ U P to 170km, in the presence of realistic detector dark counts and channel loss. Finally, we propose 
\q • a slightly more complicated scheme based on entanglement swapping that can lead to even longer 

I ' distances of communication. The limiting factor in this new scheme is the fiber loss, which imposes 

very slow communication rates at longer distances. 
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00 . I. INTRODUCTION 
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' The field of quantum information theory has brought the potential to accomplish feats considered impossible by 
— i purely classical methods. One of these is the ability to transmit an unconditionally secure message between two 

■ parties, known as quantum cryptography. The first full protocol for quantum cryptography was proposed by Bennett 
and Brassard using four different states of a quantum system 0, and has since been known as BB84. Following 
the discovery of BB84, other protocols such as the two-state and six-state schemes have been proposed ft|,[2i"f . The 

fS security of all of these protocols relies on the impossibility of an eavesdropper to measure the wavefunction of a 
quantum system without imposing a backaction on the state. This backaction will usually result in a measurable 
£^ ' increase in errors across the communication channel. 

In 1991 it was proposed by Ekert that quantum key distribution could also be implemented using non-local correla- 
tions between quantum systems [ [l6[ . Ekert pointed out that two correlated quantum systems cannot lead to violations 
of Bell's inequality if they are also correlated to a local variable which an eavesdropper can observe in order to gain 
knowledge of the measurement results. A test of Bell's inequality could then provide a statement of security against 
eavesdropping. It was later discovered that Bell's inequality is not necessary for security of Ekert 's protocol [0. An 
eavesdropper cannot obtain knowledge from a correlated quantum state without inducing errors, just as in the other 
protocols. 

The experimental effort to perform quantum key distribution began soon after the theory was established. Several 
groups have reported implementations of BB84 and other single photon schemes p^ , p8| , p8| , p3p [ . Long distance 
violations of Bell's inequality have been demonstrated in |3(| , and recently several proof-of-principle experiments using 
entangled photons have also been performed ^,^,^l|. For experimental quantum cryptography it is insufficient to 
show that tampering with the quantum channel will always result in some error. Practical systems have a baseline 
error rate which cannot be distinguished from tampering. These errors can be handled by public discussion through 
two additional steps, error correction and privacy amplification. The error correction step serves the dual purpose of 
correcting all erroneously received bits and giving an estimate of the error rate. Privacy amplification is then used 
to distill a shorter key which can be made as secure as desired. The length of this key depends on the amount of 
information which may have been leaked, and this should ideally be determined from the measured error rate and the 
laws of quantum mechanics. 
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The security of quantum key distribution against any attack allowed by the laws of quantum mechanics is a complex 
subject. Earlier work showed security for several restricted types of attacks 0,^]. Later security was proved for the 
most general individual attacks in BB84 |I3J3H,S6| , and these proofs were extended to practical photon sources in p7| . 
In an individual attack the eavesdropper is restricted to measuring each quantum transmission independently, but is 
allowed to use any measurement which is not forbidden by quantum mechanics. A more general attack allows collective 
measurements which make use of the correlations introduced during error correction and privacy amplification by 
exchange of block parities. This information can be used to refine an eavesdropper's quantum measurement. Security 
against these more general attacks has been shown in [j]]. The most general type of attack is known as a joint attack 
where the eavesdropper treats the entire quantum transmission as one system which she entangles with a probe of 
very large dimensionality. There are currently several proofs of security against this most general scenario ]29| , |2^ ,|6|,^| . 
Security against collective and joint attacks is an important milestone in quantum information theory, however the 
current proofs of security are difficult to apply to realistic systems. Furthermore, it seems practically impossible to 
implement such attacks using currently available technology. On the other hand practical systems can be rendered 
completely insecure even by very simple measurements ||. Thus, restricting Eve to only individual attacks is usually 
deemed reasonable for practical purposes. 

The security of the Ekert protocol has not been studied as closely as that of BB84. Unlike BB84, in the Ekert 
protocol the photon source is located somewhere between the sender and receiver and provides both with photons. 
Since the two communicating parties no longer have control over the source, the eavesdropper is not restricted to 
making measurements. She can take on the more aggressive strategy of blocking out the source and providing the two 
parties with her own photons. For example, she can provide each receiver with a photon in a known quantum state. 
This is the two-photon analog to the "intercept and re-send" attack in BB84, and will always result in a 25% error 
rate. A more general eavesdropping attack allows Eve to send one photon to each receiver, while maintaining a probe 
system that can be measured later on. This model was used in |^] to show that if the eavesdropper insisted on not 
causing any errors, then she could not obtain any information about the measurements at the two receivers. However, 
as previously mentioned, this is not sufficient for practical quantum key distribution. We need to know the explicit 
relationship between the error rate and amount of information leaked, which has yet to be given. Furthermore, an 
eavesdropper could send more than one photon to either receiver, and a proof of security must take this into account. 

In this paper we prove the security of the Ekert protocol against the most general types of individual attacks. In 
such an attack the eavesdropper is allowed to share any density matrix p a \, e with the two receivers. This density 
matrix describes the state of the signal sent to each receiver, and a probe state of arbitrary dimensions which the 
eavesdropper will use to infer information. Security is proved by upper bounding Eve's mutual information on the 
final key, as well as explicitly deriving an equation for the length of this key after privacy amplification. We make 
no idealized assumptions about the source, such as that it emits only one pair of photons per clock cycle. Thus, our 
results can be directly applied to practical key distribution schemes. One interesting aspect of our result is that the 
relationship between error rate and leaked information for the Ekert protocol with any source is the same as that of 
BB84 with an ideal single photon device. This indicates that, at least against individual attacks, there is no analog 
in the Ekert protocol to the powerful photon splitting attacks which severely jeopardize the security of BB84. Using 
the derived expression for the length of the final key, we calculate the communication rate for the Ekert protocol with 
ideal entangled photon sources, as well as realistic sources based on parametric down-conversion. We compare these 
rates with the communication rate for BB84 using poissonian, sub-poissonian, and ideal photon sources. It should be 
stated that some of the derivations in this paper are involved, but the results themselves are extremely easy to use, 
involving simple functions of experimentally measurable quantities. A concise review of the important equations is 
given in Section [v|. 

In Section |l| we review the general theory behind quantum key distribution. We restate some important information 
theoretic results on error correction and privacy amplification. We then derive a method for handling the side 
information leaked during error correction. This method allows us to account for the effect of error correction on 
the length of the final key. We also re-derive rates for BB84 using both poissonian and sub-poissonian light sources. 
These rates will later be used to make a comparison to the Ekert protocol. In Section III we derive a proof of security 
for the Ekert protocol, and use it to calculate expected communication rates under practical experimental conditions. 
Finally, in Section [TV] we investigate an experimental configuration based on entanglement swapping which is less 
sensitive to channel loss and detector dark counts. With some technological improvement this configuration may be 
useful for long distance quantum key distribution. 
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II. PRELIMINARIES 



In this section we provide a concise review of important concepts in quantum key distribution (QKD). We also 
derive some preliminary results which we will use in the upcoming sections. The standard participants in QKD are 
Alice, Bob, and Eve. Alice would like to exchange a secret key with Bob, which can later be used to encode the actual 
message. To do this she uses both a quantum channel and a public channel. The enemy, Eve, can listen in on the 
public channel, but is assumed incapable of altering the messages being exchanged. Eve is also allowed to make any 
measurements she can on the quantum channel. 

The secret key is formed in three steps. The first is the raw quantum transmission, which uses both the quantum 
and public channel simultaneously. The next two steps, error correction and privacy amplification, make use of only 
the public channel. After privacy amplification Alice and Bob each posses a copy of the secret key, about which Eve 
knows only a negligibly small amount of information. 



A. Quantum transmission 
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FIG. 1. Schematic of experimental setup for BB84. 



In the BB84 protocol Alice sends Bob a sequence of individual quantum bits (qubits) which randomly encode binary 
or 1. The qubits are assumed to be photons with the information encoded in the polarization, but other physical 
implementations can usually be treated in an analogous way. Alice uses two different non-orthogonal bases to encode 
her information. For example, half of the time she may encode her information along the x-y axes, and the other half 
she uses the 45° rotated axes which we will refer to as u-v. Bob randomly chooses one of the two bases and makes a 
projective measurement. After all of the quantum bits have been exchanged, Alice and Bob will publicly disclose the 
bases they used, but not the measurement results. They agree to keep only the bits in which both parties used the 
same basis. These bits form the sifted key. 

Figure [l] shows a schematic of the BB84 protocol. Bob is looking for photons in a spatial mode which we will label 
as mode a. The photons in this mode are randomly partitioned by a 50/50 beamsplitter and sent to one of the two 
polarizing beamsplitter. This technique, known as passive modulation, is an easy way to randomly modulate Bob's 
measurement basis. Passive modulation was chosen because it is easier to implement in practical systems, and also 
because it simplifies the proof of security [ p6| . In order to model the loss in the quantum channel, detectors, and 
optics, we introduce an additional beamsplitter with transmission a and a loss mode c. We can set the value of a 
to the total loss of the system and assume that the channel, detectors, and optics are lossless. The advantage of this 
approach is that it allows us to easily treat the effect of losses on the quantum state of the incoming photon. All we 
need to do is apply a beamsplitter transformation onto the photon and trace out over mode c to get its final state. 
This is not as important in the BB84 protocol since the effect of the losses is rather obvious. Either a photon is 
detected or it is not. However, when we analyze the Ekert protocol this model will prove to be extremely helpful. 

Figure |l| also shows the role of Eve. Eve tries to measure the state of each transmission that has been sent into 
the quantum channel. The most general type of individual measurement Eve can perform is a Positive Operator 
Value Measurement (POVM) jl9). In this type of measurement Eve entangles a quantum mechanical probe with each 
photon through a unitary evolution. The probe is stored coherently until all information from public discussion is 
revealed. Eve then uses all publicly disclosed information to make the best measurement on her probe. Her only 
restriction is that she measures each probe independently in compliance with the assumption of individual attacks. 
Any POVM can be characterized by a complete set of positive maps Ak which satisfy the condition 
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A k A\ = I. 



(2.1) 



If Alice sends the signal in a quantum state described by the density matrix p, the measurement backaction on the 
state is described by 



P 



(2.2) 



where p is the quantum state after the measurement. A pure state can evolve into a mixed state through this type of 
intervention. The probability that Eve will measure her probe in the state k is given by 



p{k) = Tr{A kP A\y 
while the probability that Bob measures outcome ip is 

p{^,k)=Tv[A kP AlE^, 



(2.3) 



(2.4) 



where denotes the projection operator onto the state 

Unlike BB84, in the Ekert protocol both Alice and Bob are recipients of a signal. The source of this signal is 
presumed to be somewhere in between both parties. In the ideal case each party receives one of a pair of photons in 
a quantum mechanically entangled state. For example, the two photons may be in the state 
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|V>) = (\xx) + \yy)) , 



(2.5) 



which implies that if both receivers measure their photon in the x-y basis, their measurment results will be completely 
correlated. However, one can rewrite the above state in the completely equivalent form 
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IVO = -/= (\uu) + \vv)) 



(2.6) 



Thus, if both receivers choose to measure in the u-v instead of the x-y basis their measurement results will remain 
correlated. This suggests the following protocol for quantum cryptography. Each receiver measures their respective 
photon randomly in either the x-y or u-v basis. Later they agree to keep only the instances in which the measurement 
bases were the same, forming the sifted key. 

Figure || shows a schematic of a key distribution experiment based on the Ekert protocol. In this experiment Alice 
is assumed to monitor mode a, and Bob mode b. Both parties use passive modulation to switch their basis. As before, 
we insert an additional beamsplitter into each arm to account for the losses and presume that the channel, optics, 
and detectors are all lossless. 
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FIG. 2. Schematic of experimental setup for Ekert protocol. 
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In the Ekert protocol, the role of the Eve is also modified. Since she now has complete control over the source, Eve 
is not restricted to making measurements on the photons. In fact, she can can completely block out the source and 
provide the two receivers with any signal she chooses, as shown in Figure |[ For example, Eve can send both receivers 
a photon polarized along the x axis. If Alice and Bob measure in the x-y basis then she will know their measurement 
result. But if they choose the u-v basis, then their measurements are completely random, resulting in a 50% error 
rate. This is the equivalent version of the intercept and re-send strategy in BB84. A more general attack strategy is 
to generate a pure state consisting of one photon for Alice, one for Bob, and some probe which Eve can later use to 
infer the measurement results. The most general pure state of this type that Eve can generate is 

|Vw) = \xx)\P xx ) + \yy)\P yy ) + \xy)\P xy ) + \yx)\P yx ), (2.7) 

where |P XX )> \Pyy)i Wxy), and \Pyx) are the states of her probe and are not assumed to be orthogonal or normalized. 
As with BB84, she can store her probe until all public information is revealed, and use this to refine her measurement. 
But even this is not completely general, because Eve could send a mixed state instead of a pure state. Furthermore, 
she may decide to send more than one photon to either Alice or Bob if this is advantageous. The most general state 
that Eve can generate is a density matrix p a be, which spans the entire Hilbert space of Eve's probe, as well as the 
entire photon number manifold of Alice and Bob. Once again it should be emphasized that we are restricting Eve to 
individual attacks, which means that she measures her probes independently, and that p a b e is independently generated 
for each clock cycle. 

It is important to point out one additional subtlety regarding security of the Ekert protocol. In the above model we 
assume that Eve is in fact sending photons, and not some other particle. This assumption may seem silly, but appears 
unavoidable, at least if one insists on using passive modulation. The reason for this is that both receivers take for 
granted that the optics they are using perform the measurement which they intended. They rely on the polarizing 
beamsplitters to make a projective measurements in the polarization basis, and the 50/50 beamsplitter to randomly 
partition the photons. Suppose that Eve has access to a mysterious particle which is also capable of triggering a 
detection event in the photon counters. However, assume that this particle has a spin angular momentum of 3/2. 
Furthermore, the particle interacts in such a way that the 50/50 beamsplitter reflects the 3/2 and 1/2 spin states, but 
transmits —3/2 and —1/2. The polarizing beamsplitters instead reflect 3/2 and —3/2, but transmit 1/2 and —1/2. 
If Eve sends this strange unnamed particle instead of a photon she has complete control over the detection events 
at both receivers. Although it is highly unlikely that such a particle exists, it is a very difficult claim to prove. It 
has been recently shown that this loophole can be circumvented if Alice and Bob rapidly switch their measurement 
basis |0. However, this method requires very low loss, which is extremely difficult to achieve with practical systems. 

B. Error correction 

In any realistic communication system errors are bound to occur, and some form of error correction is required. In 
quantum cryptography the errors typically arise from technological imperfections in the optics and detectors, but can 
also come from eavesdropping. In order to achieve noise free communication these errors must be corrected, and this 
can be done through public discussion. 

Following the raw quantum transmission Alice, Bob, and Eve each possess the strings X, Y, and Z respectively. In 
order to correct the errors, Alice and Bob exchange an additional message U such that knowledge of string Y and U 
leave very little uncertainty about string X. One way to mathematically express this is to use the Shannon entropy 
function 

H(X) = -J2p(x)log 2 p(x). (2.8) 

X 

The conditional entropy function H{X\Z = z) is defined as above using the conditional probability distribution 
p(x\Z — z). The average conditional entropy H(X\Z) is simply defined as 

H{X\Z) = ^2p{z)H(X\Z = z). (2.9) 

z 

The message U should provide Bob with enough information so that H(X\YU) ~ 0. Since string U is publicly 
disclosed Eve may learn additional information as well, but good error correction algorithm will reduce this information 
leakage to a minimum. Unfortunately, given the error rate e, a lower bound exists on the minimum number of bits in 
U. This limit, which is a variant of the Shannon noiseless coding theorem can be stated as 
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Urn ->h(e), (2.10) 

n — >oo fi 

where n is the length of the string, k is the number of bits in message U , and h(e) is the conditional entropy of a 
single bit over a binary symmetric channel which is given by 

h(e) = -eloge- (1 - e)log(l - e) . (2.11) 

An error correction algorithm should ideally operate very close to this limit. At the same time the algorithm should 
be computationally efficient or the execution time may become prohibitively long. 

Error correction algorithms can usually be divided into two classes, unidirectional and bidirectional algorithms. In 
a unidirectional algorithm information flows only from Alice to Bob. Alice provides Bob with an additional string 
U which he then uses to try to find his errors. Unidirectional algorithms that are both computationally efficient 
and operate near the Shannon limit are difficult to find H@. 

In a bidirectional algorithm information can flow 
both ways, and Alice can use the feedback from Bob to determine what additional information she should provide 
him. This makes it easier to construct efficient algorithms. These two classes can be further subdivided into two 
subclasses, one for algorithms which discard errors and one for those which correct them. Discarding errors is usually 
done in oder to prevent additional side information from leaking to Eve. Algorithms which correct errors allow for 
this additional flow of side information and account for it during privacy amplification. Since privacy amplification is 
typically a very efficient process, algorithms which correct the errors tend to perform better 

The communication rate in QKD strongly depends on the type of error correction algorithm used. In order to get 
an estimate of this rate we must at least decide on which of the four subclasses the algorithm belongs to. Since we are 
interested in practical systems, and because efficiency is very important in quantum key distribution, we will assume 
that the algorithm is bidirectional and corrects the errors. An example of such an algorithm can be found in |lC[ |. 

C. Privacy amplification 

After error correction, Alice and Bob share an error free string X. Eve has also potentially obtained at least partial 
information about this string from attacks on the raw quantum transmission and side information leaked during 
error correction. In pq ] it is shown that even with a measured error rate of 1% — 5% a non-negligible amount of 
information on string X could have been revealed. Thus X cannot by itself be used as a key. However, through the 
method of generalized privacy amplification || , the string X can be compressed to a shorter string K over which any 
eavesdropper has only a negligible amount of information. The amount of compression needed depends on how much 
information may have been compromised during the previous phases of the transmission. 

To do privacy amplification Alice picks a function g out of a universal class of functions Q which map all n bit 
strings to r bit strings where r < n (see jj| for more details). Once g has been picked and publicly announced both 
parties calculate the string K = g(X), which serves as the final key. This key is considered secure if Eve's mutual 
information on K, defined as |T^| 

Ie(K;GV) = H(K) — H(K\GV), (2.12) 

is negligibly small, where G is the random variable corresponding to the choice of function g and V is all the information 
available to Eve. 

An important quantity in the analysis of privacy amplification is the collision probability defined as 

P C (X) = 5> 2 (z). (2.13) 

X 

One can show that the conditional entropy H{K\G) is bounded by ^ Thm. 3] 

H(K\G)>r-^P c (X) (2.14) 

This theorem can be applied to conditional distributions as well, which leads to 

H(K\G,Z = z)>r-f-P c (X\Z = z), (2.15) 
In 2 

where P C (X\Z = z) is just the collision probability of the distribution p(x\Z = z). By averaging both sides of the 
above equation we get 



G 



H(K\GZ)>r-^-{P c (X\Z = z)) z , (2.16) 
in 2 

where 

(P C (X\Z = z)) z = Y,P(z)Pc(X\Z = z) (2.17) 

z 

is the average collision probability. This is a quantity of central importance in privacy amplification. In the case of 
individual attacks, the i'th bit in Z depends only on the i'th bit in X. Under these circumstances the average collision 
probability factors into the product of the average collision probability of each bit. Thus, 

(P c (X\Z = z)) z = (p c ) n , (2.18) 

where n is the number of bits in string X and 

" P 2 (a, 0) 



EE 



a=0, 1/3=1 



(2.19) 



In the above expression a sums over the possible values of a single bit in Alices string and (3 sums over the possible 
measurement outcomes of the probe, which are enumerated from 1 to k. Suppose that we are able to come up with 
a bound of the form — log 2 (P c {X\Z = z)) z > c. If we set r = c — s, where s is a security parameter chosen by Alice 



and Bob, then ( [2.16] ) leads to 



I E (X;Z) < 2~7 In 2. (2.20) 



Thus, a bound on the average collision probability tells how short we should make string K. 

Before concluding this review of the main concepts in privacy amplification we would like to make a few comments 
on the notion of security in QKD. As stated above we consider the key secure if the mutual information is very small. 
One might raise concerns about this definition of security. The mutual information can be interpreted as the average 
number of bits Eve will obtain on the final key. In any given experiment it is possible that Eve can obtain significantly 
more bits than the average, but this happens with small probability. Perhaps a more satisfactory notion of security 
would be a statement of the form, with probability no greater than s Eve obtains no more than ? bits of information 
on the final key. The mutual information is an important quantity because it allows us to make such a statement. A 
simple method for doing this is to use the Markov bound 

P { IX)< I ^ GUZ \ (2.21) 

where / is the actual number of bits of information Eve has obtained. Setting ? = 1 gives us a bound on the probability 
that Eve obtains more than one bit of information on the f inal s tring. This may serve as a more convincing statement 



of security than statements about the average. Plugging (2.20) into the above expression shows that the probability 



that Eve obtains more than one bit on the final key is exponentially small in the security parameter s. 



D. Handling side information from error correction 



If the only information available to Eve comes from string Z, which is obtained from attacks on the quantum 
transmission, then the discussion in the previous section is sufficient. But in the case of bi-directional error correction 
Eve will also learn an additional string U which gives her more information about Alice's key. This side information 



must also be included in the calculation. We can apply the bound in ( 2.14 ) to the conditional distribution p{x\U = 
u,Z = z), which leads to 

2 r 

H(K\G, U = u,Z = z)>r P C (X\U = u, Z = z). (2.22) 

In 2 

We can then try to average both sides of the above expression but doing this introduces additional complications. 
The random variable U introduces correlations between different bits in strings X and Z. Because of this the average 
collision probability no longer factors into the product of individual bits, as in ( [2.18] ). This makes the problem of 
finding a bound on the average collision probability significantly more difficult. This problem has been previously 
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investigated in M|, where several bounds on the collision probability P C (X\Z = z,U — u) were derived. But the 
extension of this work to the average collision probability involves a few subtleties, which we deal with in Appendix |a|. 
In this appendix we show that if we set 

V = TIT — K — t — S, (2.23) 

where 

T = -log 2 p c , (2.24) 

k is the number of bits in message U, n is the length of the error corrected key, and both s and t are security 
parameters chosen by Alice and Bob, then 

Ie< 2-*r+^4- (2.25) 
In 2 

This bound on Eve's information is still exponentially small in the security parameters, and only involves the collision 
probability averaged over her measurements on the quantum transmission. 



E. Communication rates for BB84 



The main effort in provin g sec urity of quantum key distribution against individual attacks comes down to finding 



a bound for p c , defined in ( [2.19 ). This bound should come from the laws of quantum mechanics. The quantity p c 
has been extensively studied by Liitkenhaus in the context of the BB84 protocol |Q . In this work several bounds 
are derived using the model of a POVM, which Eve performs on each quantum transmission. Liitkenhaus points 
out that it is better not to discard any signals, even ambiguous dual fire events, in order not to open up a security 
loophole. Monitoring the dual fire events can be very useful to prevent Eve from sending Bob additional photons. 
This is precisely why we picked passive modulation, where the 50/50 beamsplitter randomly partitions all incoming 
photons. If Eve uses more than one photon she will cause dual fire events with very high probability. By keeping 
track of these events and dealing with them during error correction, Alice and Bob can make it unfavorable for Eve 
to employ such tactics. One convenient way to keep track of dual fire events is to define a disturbance measure 

n err + w D n D 

e= , (2.26) 

n rec 

where n rec , n erri and no are the number of error corrected bits, error bits, and ambiguous dual fire events respectively, 
and w d is an independently chosen weighting parameter. The value of wd should be made sufficiently large so that 
it is to Eve's advantage to only use single photons. It is shown in |2(| that if the passive modulation scheme is used 
and Wjj is set to 1/2 the collision probability can be bounded by 

p c <i + 2e-2e 2 . (2.27) 

Throughout our calculations we will assume that dual fire events are very rare. In this limit we have e = e, where e 
is the error rate. This approximation is usually reasonable, and is extremely good in the limit of large loss which is 
what we are mainly interested in. 

The above bound on the collision probability is valid for the BB84 protocol only if the photon source never injects 
more than one photon into the channel. However, practical photon sources sometimes inject a multi-photon state. 
These states are vulnerable to photon splitting attacks where Eve splits one of the photons from the pulse and leaves 
the remaining ones undisturbed. This can be done with a Jaynes-Cummings type interaction [^J. She can store this 
photon coherently until the measurement basis is revealed, after which she learns the exact value of the bit. The 
most powerful types of photon splitting attacks will also presume that Eve has access to lossless optical fibers. This 
allows her to transmit the remaining photons from a multi-photon states with unity probability. At the same time 
she blocks off a fraction of the single photon states while conserving the overall transmission rate, giving her complete 
knowledge over a larger fraction of the sifted key. The extension of security for realistic sources which sometimes 
create a multi-photon state is given in |2j| . Each multi-photon state can in principle result in a collision probability 
of one while producing no errors. This can be accounted for by first defining the parameter 

= Urec - Hm (2.28) 
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where n m is t he number of transmissions in which more than one photon was injected into the channel. The definition 



of t in ( 2.24 ) should then be modified to J27[ 

r=-/31og 2 p c (e//3), (2.29) 



where p c is the collision probability of a single photon state which is bounded by (2.27). 

We can now put all the previously discussed elements together to calculate the communication rate of the BB84 
protocol with both ideal and realistic photon sources. An ideal source generates exactly one photon every clock cycle 
of the experiment. Such sources are beyond current technological capabilities, so most implementations of BB84 use 
photon sources based on attenuated coherent light. In such schemes the number of photons N in each pulse follows 
a poisson distribution 

- n j 

P(N = j) =e~ n — (2.30) 

r- 

where n is the average number of photons per pulse. The average photon number should be made sufficiently low 
so that the the probability of injecting more than one photon into the channel is small. At the same time n cannot 
be made small without having a larger fraction of the pulses contain zero photons. The average number should be 
chosen carefully to balance both effects. 

After the source emits a pulse its polarization is set by an electro-optic modulator, and the signal is injected into the 
channel. It is detected by Bob with some probability which depends on fiber losses, the quantum efficiency of Bob's 
detector, and any other loss mechanism in the system. We assume that the channel transmission is an exponentially 
decaying function of distance. Thus, the channel transmission Tp can be written as 

T F = 10-( <7 V10) ) (2.31) 

where a is the loss coefficient. As previously discussed, we combine all losses from the channel, detectors, and optics 
into one beamsplitter with transmission 

oll = rjTp (2.32) 

and one loss mode c, which is shown in Figure [|. The subscript L is used to denote that the loss is a function of 
distance. The factor r\ accounts for all constant losses in the system such as detector inefficiency and reflection loss 
from optics. 

In a practical system detection events can also arise from dark counts in the detection unit. The probability that 
a detection event occurs can be written as 

Pclick — Psignal T" Pdark PsignalPdark: 

(2.33) 

where p S i gn ai is the probability that the detector registers a count due to a photon, and pdark is the probability it 
registers a dark count. If the probability of a simultaneous signal and dark count event is negligibly small we can 
write 

Pclick ~ Psignal + Pdark- (2.34) 

The expression p S i gn ai can be written as 

oo 

Psignal = $^p(t)(l - (1 - (2.35) 

i=l 

where p(i) is the probability the source generated i photons. For an ideal source p(l) = 1 and we have the rather 
trivial result that p signal — otp. For a poissonian light source we can derive the closed form solution 

Psignal = I- e~ aLn . (2.36) 

We assume that all detectors have the same dark count rate, and define d as the probability of having a dark count 
within the measurement time window. If we neglect the events where more than one dark count is detected in a clock 
cycle then 

Pdark = 4cL (2.37) 



9 



Thus, the error rate e is given by 

Pdark /2 ~t~ PPsignal ^ ^§) 

where [i takes into account the error rate of the signal photons, which may result from imperfect polarizing optics or 
channel distortion. The expected number of bits in the error corrected key, n rec , is given by 

ntotPclick 

where n to t is the total number of pulses sent by Alice. 



(2.39) 



We now need estimate of (3 defined in ( 2.28 ). In the limit of long strings (3 becomes 



(3 = PcUck Pm . (2.40) 

Pclick 

where p m is the probability that more than one photon is injected into the channel by a pulse. An ideal source never 
emits more than one photon we so p m = 0. For poisson light we have 

p m = 1 - (1 + n)e- n , (2.41) 

Finally, we need to take into account the side information leaked by the correction. We define the function /(e) in 
the same way as was done in p?| . This function determines how far off from the Shannon limit the error correction 
algorithm is performing. Thus, 

lim — = -/(e) [e log 2 (e) + (1 - e) log 2 (1 - e)] . (2.42) 

n,. cc — >oo n rec 

The value of /(e) can be determined by benchmark tests. Such tests have been performed for the algorithm given 
in PJ, and values for /(e) taken from this experiment are shown in table |. We interpolate these values to determine 
/(e) for intermediate values of e. 



e 


f(e) 


0.01 


1.16 


0.05 


1.16 


0.1 


1.22 


0.15 


1.35 



TABLE I. Benchmark performance of error correction algorithm. 
We can now put everything together. Using ( 2.23| ) one finds 



r = nrec ( Me/ (3) - — )-«-*, (2.43) 
with the expression for n rec given in ( [2.39] ). One can then define the communication rate Rbb84 a s 

T 

Rbb84 = lim 

n tot ^co ntot 

= P£lp {(3T (e/P) + /(e) [e log 2 (e) + (1 - e) log 2 (1 - e)]} . 

This is the normalized rate per clock pulse, which can be multiplied by the clock rate of the source to get the actual 
bit rate. 

III. SECURITY OF THE EKERT PROTOCOL 

In this section we tackle the problem of proving secur ity for the Ekert protocol. As shown in the previous section, 
this involves finding an upper bound on p c given in ( 2.19| ) using the laws of quantum mechanics. We derive this bound 



by allowing Eve to generate any density matrix p a \, e which she will share with Alice and Bob. We then calculate the 
communication rate for the Ekert protocol in the presence of detector dark counts and channel losses. This is done 
for both an ideal source which creates exactly one entangled pair per clock cycle, as well as a more practical source 
based on parametric down-conversion. 
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A. Proof of security against individual attacks 



We begin the proof of security by defining the Hilbert space over which Alice and Bob make their measurements. 
Alice and Bob's signal are assumed to be distinguishable by their spatial and momentum states. Let us assume that 
Alice's photon is in mode a and Bob's photon is in mode b. The most general photon signal in these two modes can 
be written as a linear superposition of the eigenstates 

\ip)ab = \ni,n 2 ) a \n3,ni) b (3.1) 

where n\, and n% are the number of photons in the x and y polarization of mode a, and 713 and 714 are the number of 
photons in the x and y polarization of mode b. 

Eve is allowed to pick any density matrix p a b e which represents some entangled state of her probe and the signals 
transmitted to Alice and Bob. She can send any number of photons she wishes, or a coherent superposition of photon 
numbers. We first define the disturbance in the same way as ( 2.26| ). The only difference is that now both Alice and 



Bob could see a dual- fire event, so po is interpreted as the probability that either sees such an event. 

We assume that Eve has complete control over whether a photon is detected or not, so she can provide any density 
matrix p a b e of her choosing. Our first step is to show that Eve's best strategy is to keep track of how many photons 
she is sending to both receivers. This is done in Appendix |b], where we first show that off diagonal terms in p a b e which 
couple different photon number states sent to Alice and Bob do not contribute to any measurement results. This is 
simply a consequence of the detection apparatus used by Alice and Bob, which is composed of passive linear optics 
and photon counters. These elements alone cannot distinguish between a coherent superposition and random mixture 
of photon number states. By keeping track of how many photons she is sending Eve destroys these off diagonal terms. 
But since they never factor into the measurements she can do this without effecting the disturbance, and knowing 
the number of photons received can potentially refine her attack. 

The main consequence of the above result is that the most general density matrix p a b e can be assumed to be in the 
block diagonal form 



Pa b e. = £ Pit (3.2) 

where p^ e spans the subspace where Alice is sent i photons and Bob is sent j photons. Furthermore, because 

Eve knows how many photons were sent her collision probability can be broken up into different photon number 
contributions as 

00 (ij) 

p c =Y, P —p ( ! j \ (3.3) 

where 

(ij) _ \- 1 p 2 (jj,m) 



Pc 



V (3.4) 



J pirn] 

The set M^> is defined as the set of all measurement results on Eve's probe if she sent i photons to Alice and j 
to Bob, and p^H is the probability that the signal component p^P enters the error corrected key. We can similarly 
break up the disturbance measure e into different photon number contributions as 

1 

-e<*ft. (3.5) 



"V - 



(ij) Jij) , ,„_,„(«) . „(»i) 

rec yerr \ W DFD Prec Uj\ 

W) = 2^ ' 

ij 



Prec if 



In the above expression p£rr is the probability that p^ e enters the sifted key as an error, and p\p is the probability 
that it causes a dual fire event. 

Our next step is to investigate the term p^ 1 ■ In Appendix ^ we show that this term is bounded by 

p(ii)<I + 2e ( 11 )-2f6( 11 )) 2 . (3.6) 
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Once this is established, we show in Appendix [S] that if the weighting parameter we in (3.5) is set to 1/2 than Eve's 
optimal strategy is to only send one photon to Alice and Bob. Given that this is the optimal strategy one is led 
directly to the result 



Pc < 



2e - 2e 2 



(3.7) 



which is exactly the same collision probability given in (2.27). 

Our proof makes no idealized assumptions about the entangled photon source, such as that it only emits one pair 
of photons per clock cycle. As a matter of fact the source never enters the picture since we assume that Eve blocks it 
out and replaces it with the best possible source allowed by the laws of quantum mechanics. The error rate and dual 
fire rate alone are enough to put a bound on her collision probability. 



B. Ideal entangled photon source 

Before analyzing practical entangled photon sources for the Ekert protocol we will first analyze the simpler case of 
an ideal entangled photon source. This source is assumed to create exactly one pair of photons per clock cycle, whose 
quantum state is given by 

\1>+) = ±QHV) + \VH)). (3.8) 

Although proposals for creating such a source exist Q, we do not know of any successful implementations of this 
proposal to date. Nevertheless, this simplified analysis will set the groundwork for the analysis of entangled photon 
sources based on parametric down-conversion. 

When doing two photon experiments, one is no longer interested in individual detection events. Instead, one looks 
for coincidence events where two detectors simultaneously fire. We separate the coincidence probability into two parts, 
Ptrue is the probability of a true coincidence from a pair of entangled photons, and p false is the probability of a false 
coincidence which for an ideal source can only occur from a photon and dark count, or two dark counts. We write 

Pcoin Ptrue T" P false: 

(3.9) 

where once again the probability of a simultaneous true and false coincidence are considered negligibly small. 



First we need to decide where to put the source. Using the definition in (2.32), we set the source a distance x from 
Alice and L — x from Bob. Then 

Ptrue — (Xx&L — x: 
= OIL, 

and 

Pfaise = a x (1 - a L - x ) 4rf(l - d) 3 + a L _ x (1 - a x ) 4d(l - df + 16d 2 (l - df . (3.10) 

It can be seen that the probability of a true coincidence does not change with x, but the false coincidence rate does. 
A simple optimization shows that the false coincidence rate achieves a minimum halfway between Alice and Bob. At 
this optimal location the false coincidence rate is 

Pfaise = 8a L / 2 d + 16d 2 , (3-H) 

where we keep only terms that are quadratic in and d. Higher order terms can be ignored because they correspond 
to more than one detection event at either receiver. The error rate e is 

e _ Pfaise/ '2 + UPtrue ,g ^ 

Pcoin 

which then leads to an expression for the communication rate REkert 

REkert = ^ Me) + /(e) [e log 2 e + (1 - e) log 2 (1 - e)]} . (3.13) 
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C. Entangled photons from parametric down-conversion 



A more practical way of generating entangled photons is to use the spontaneous emission of a non-degenerate para- 
metric amplifier. This technique, known as parametric down-conversion, is extensively used to generate entanglement 
in polarization as well as other degrees of freedom such as energy and momentum. Parametric amplifiers exploit the 
second order non-linearities of non-centrosymmetric materials. These non-linearities couple three different modes of 
an electromagnetic field via the interaction Hamiltonian (39) 

Hi = iUx^Ve^-^-^attf + h.c. 

where modes a and b are treated quantum mechanically while the third mode Ve lu)t is considered sufficiently strong 
to be treated classically. The state of the field after the nonlinear interaction is given by 



exp 



1 f T 

/ Hj(t)dt 



|0>. 



We assume the energy conservation condition, lj = u a + uj^ , which leads directly to 

\if>) = e*( at5t - a5 )|0), 

where the parameter x depends on several factors including the non-linear coefficient X i t ne pump energy, and the 
interaction time. Using the operator identity | j39f 

eX (at6t_ab) _ e ra+6+ e - 3 (a+a+bth + i) e _ra^ (3-14) 

where 

r = tanh x 
g = In cosh x, 



directly leads to the relation 



^tanh"xl«») & (3.15) 



coshx 

The above equation makes it clear that whenever a photon is detected in one mode, the conjugate mode must also 
contain a photon. In order to generate entanglement in polarization one needs to create a correlation between the 
polarization of these two modes. This is typically done using non-colinear Type II phase matching | p3| , which leads 
to the slightly more complicated interaction 



Ei 



where x an d y r efer to the polarization of the photon. Since all creation operators in the Hamiltonian commute, we 
can apply ( 3. 14 ) to both mode pairs which directly leads to 



cosh x 

In the limit of small x °ue can make the approximation 



tanh v('a t 6 t +o t b'n 

2 10) (3.16) 



IV) « V / l-2x 2 |0)+V2x(|l)aJl) b jO) Q jO)^ + |0) Q jO) b Jl) Q Jl) b J (3.17) 

Thus, a parametric down-converter creates an approximate Bell state if x is sufficiently small to ignore higher order 
contributions. But x cannot be made small without sacrificing the rate of down-conversion. 

We want to calculate the probability p CO i n and the error rate e as a function of the parameter x, as well as the 
optical losses and dark counts of the detectors. We begin by defining the field operator 

tanh X (a+6t+at6t) 

V = -3 . (3.18) 

cosh x 
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The beamsplitter model that we have introduced previously to account for the losses becomes very useful here. The 
beamsplitters perform a unitary operation on the modes which is given by 



a a — * sJOL L j2a a + y/l = a L/2C<r, 



where a represents polarization and the modes c and d are the reflected modes of the beamsplitter. To determine the 
state of the photons after the loss we first apply this beamsplitter transformation. To simplify the notation we define 
another field operator 



where p and <j> are any two independent modes. Using this definition, ( 3.1q ) is transformed by the two beamsplitters 
into 



1 

2 — exp 

cosh x 



tanh x a L/2 ^ab + Ja L / 2 (l - a L / 2 ) (Vw + ipbc) + (l - a L/2 ) ip c d 



We can expand this expression in terms of aJ and w as 
1 



exp [tanhx (l - a L/2 ) ipcd] + 



tanh x 7. 



n=l 



cosh x 

a-L/2 (nipab + n(n - 1) (l - a L/2 ) 4> a d4>cb)] + ^d} 



nJ a L/2 (l - a L/2 ) (tp ad + ip cb ) 



where ipo is the wave operator which contains all the terms that create more than one photon in either modes. It is 
now necessary to operate on the vacuum and trace out over modes c and d to get the final density matrix. As shown 
in Appendix M we can ignore any off diagonal terms that couple different photon number states because they do not 
contribute to the signal. We define the density matrix as the two photon density matrix in which the photons 



are in the entangled state \ip+) given in (3.8). The matrices an( i Po represent a zero photon vacuum state in mode 
a and b respectively. Finally we define the matrices p% and p h u as 



Pu 



(3.19) 



where / is the identity matrix. The above matrices correspond to an unpolarized photon in mode a or b respectively. 
After tracing out loss modes c and d the density matrix becomes 



Pab = Ap. 4 , + +Bp a ®p b + C (pi ® p b + p a ® p b u ) + Dp a u ® p b u + (1 - A - 2B - C - D) p D , 



(3.20) 



where pp is the matrix which represents all the possible states in which more than one photon is in either mode a or 
b after the losses. The coefficients A,B,C, and D are 



.4 



B 



C = 



1 



2a 2 L , 2 tanh 2 x 



cosh x 


^1 - tanh 2 x (l - 


«L/ 2 ) 2 ) 


1 


1 




cosh x 


^1 - tanh 2 x (l - 


a L/2f) 


1 


2«L/2 (l - Ot L / 2 ] 


tanh 2 x 



D = 



cosh x(i_ tai v x(1 _ aL/2 r 

1 4a 2 (l — aL/2) 2 tanh 4 x 
cosh 4 x 1 - tanh 2 x (l - a L/2 ) 4 



(3.21) 
(3.22) 
(3.23) 

(3.24) 



In the above expression, A is the probability that Alice and Bob share an entangled pair of photons. This component 
on the signal will be defined as a true coincidence, because it leads to error free transmission. The coefficient B is 
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then the probability that neither receiver gets a photon, either because the source failed to generate a pair or because 
all photons where lost. Similarly, C is the probability that one of the two receivers gets a photon but the other does 
not. In order for these signals to be factored into the key the must be accompanied by dark counts. Coefficient D 
is the probability that both receivers get a photon, but these photons are unpolarized and uncorrelated. Note that 
D is at least fourth order in tanh%, indicating that at least two pairs must be created in order for it to exist. The 
intuitive explanation for the presence of this unpolarized component is that when higher order number states are 
created, and some of these photons are lost, the loss mode c and d play a similar role to Eve. The photons in this 
mode can potentially carry some information about the quantum state of the other photons, and will thus result in 
decoherence. Since this component of the signal causes a 50% error, we can lump it into the definition of a false 
coincidence. Hence, 

Ptrue 

p false = 16d 2 B + 8dC + D 



The communication rate can be calculated by simply plugging these expressions into (3.12) and (3.13) 



D. Calculations 



a) 
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FIG. 3. Comparison of communication rate for BB84 and Ekert protocol. Plot (a) is for 1.5/un fiber optical communication 
experiment. In this wavelength r\ = 0.18, d = 5 x 10 -5 , and the channel loss a is set to 0.2dB/km. For the Ekert protocol the 
distance is the total separation between Alice and Bob. Plot (b) shows calculated values for free-space quantum key distribution 
with visible photons. The rate is plotted as a function of the total loss, including detector quantum efficiency. The detectors 
are assumed to have a dark count rate of d = 5 x 10 -8 . For the Ekert protocol the loss is the total loss in both arms. 
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We now use the previously derived equation to calculate the rate of quantum key distribution using both the Ekert 
protocol and BB84. We perform simulations for fiber optical and free space key distribution experiments. For the 
fiber optical simulation we look at the 1.5^m telecommunication window, while for free space communication we 
focus on the visible wavelengths where single photon counters tend to perform best. In free space communication the 
channel loss is no longer an exponential function of distance. Instead, it is a complicated function which results from 
atmospheric effects, beam diffraction, and beam steering problems. Thus for free space we are more interested in the 
rate as a function of the total loss rather than distance. 

Figure || shows the calculation results, for both BB84 and Ekert protocols with ideal and realistic sources. In plot 
(a) of the figure we show results for fiber optical communications. Using experimental values from || we set the 
detector quantum efficiency to 0.18, d — 5 x 10~ 5 , and the channel loss a — 0.2dB/km. We also set the baseline error 
rate fj, = 0.01, and add an extra ldB of loss to account for losses in the receiver unit. The curves corresponding to 
the Ekert protocol plot the distance from Alice to Bob, with the source assumed halfway in between. Plot (b) shows 
calculations for free space quantum key distribution. The communication rate is plotted as a function of the total 
loss, including the detector quantum efficiency. In the free space curves for the Ekert protocol we again put the source 
halfway between Alice and Bob and plot the rate as a function of the total loss in both arms. The dark counts of the 
detectors are set to 5 x 10 -8 . In the curve for BB84 with a poisson light source the average photon number n is a free 
adjustable parameter. Similarly in the Ekert protocol with parametric down-conversion we are free to adjust x- F° r 
both cases we numerically optimize the communication rate at each point with respect to the adjustable parameter. 

Each curve features a cutoff distance where the communication rate quickly drops to zero. This cutoff is due to the 
dark counts, which begin to make a non- negligible contribution to the signal at some point. However the two curves 
for the Ekert protocol feature a much longer cutoff distance than the BB84 counterparts. This is due partially to the 
absence of the photon splitting attacks. But even when performing BB84 with ideal single photon sources, which don't 
suffer from photon splitting attacks either, the cutoff distance for the Ekert protocol is still significantly longer. The 
reason for this is that in the Ekert protocol, a dark count alone cannot produce an error. It must be accompanied by a 
photon or another dark count, and thus is much less likely to contribute to the signal. The difference in rates between 
t he id eal EPR source and t he pa rametric down-converter can be attributed to the interplay between coefficient A in 
(3.22), and coefficient D in (3.24). Term A is the probability of a real coincidence, and increases with \- Term D on 
the other hand contributes to false coincidences and increases with x as well, but is of higher order. One cannot make 
A arbitrarily large without getting an increased contribution from D. This leads to an optimum value for x which is 
less than one. 



IV. ENTANGLEMENT SWAPPING 
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FIG. 4. Experimental setup for quantum key distribution with entanglement swaps. 

In this section we analyze a more complicated scheme based on entanglement swapping. Figure ^ gives a diagram 
of the proposed configuration. A series of entangled photon sources, which we assume to be ideal sources, are spread 
out an equal distance distance apart from Alice to Bob. The sources are clocked to simultaneously emit a single pair 
of entangled photons. Each of the pair is sent to a corresponding Bell State Analyzer, whose actions is to perform an 
entanglement swap. If all the swaps have been successfully performed, Alice and Bob will share a pair of entangled 



1G 



photons. Experimental demonstrations of a single entanglement swap can be found in [ p2[ . Entanglement swapping 
is a key element for quantum repeaters, which use entanglement purification protocols to reliably exchange quantum 
correlated photons between two parties 0|. We show that even without such protocols, using only linear optical 
elements, photon counters, and a clocked source of entangled photons, swapping can enhance the communication 
distance. 

The key element to the scheme is the Bell Analyzer. Since we restrict ourselves to passive linear elements and 
vacuum auxiliary states we cannot achieve a complete Bell Measurement. It has recently been shown that Bell 
Analyzers based on only these components cannot have better than a 50% efficiency . One scheme which achieves 
this maximum is shown on the inset of Figure ^. This scheme will distinguish between the states 

|^ ± > = j=(\HV) ± \VH)) (4.1) 

but will register an inconclusive result if sent the states 

\<P±) = -^=(\HH)±\VV)) (4.2) 

The state generated by the entangled photon sources is assumed to be \tp+). Considering only a single swap, we 
can write 

|^+)l2|^+)34 = g [|V ? +>23l'^+>14 ~ |^l_>23|^->14 + 10+) 23^+) 14 ~ 1 4>- ) 23 1 <f>- ) u] (4-3) 

The above expression makes it clear that a Bell measurement on photons 2 and 3 leaves photons 1 and 4 in an 
entangled state, and the measurement result tells which one. After N such Bell measurements photon 1 and 27V will 
be entangled, and the N Bell measurement results will allow Alice and Bob to know which entangled state they share. 
Knowledge of this state allows them to do entangled photon key distribution and interpret their data correctly. Since 
our Bell analyzer has an efficiency of only 50%, in the best possible case we will pay a price of 2~ N in communication 
rate. 

Consider the single swap. We will define a to be the detection probability for each photon. The probability that 
both photon 2 and 3 reach the Bell analyzer and are successfully projected is 

Pl r Z P = (4.4) 

If a photon is lost in the fiber or due to detector inefficiency the Bell analyzer may still indicate that a Bell measurement 
has been performed due to detector dark counts. The probability of this happening is 



P 



f^; = 6ad+12d 2 . (4.5) 



Defining the factor 



inswap 



Pswap ' Pswap 



(4.6) 



it is straightforward to show that, given the Bell analyzer registered a successful Bell measurement, the density matrix 
of photons 1 and 4 is given by 

piA = 9P^± + 0-~9)j (4-7) 

where p^ ± is the pure state or \ip~) depending on the measurement result. 
For the case of N entanglement swaps the detection probability for each photon is 

a — r/10~ lo <2"+ 2 > , (4.8) 

where L is the distance from Alice to Bob. It is again straightforward to show that after TV swaps, the state of photon 
1 and 27V is 

Pi,-ZN = 9 N P^ + {1-9 N )\ (4.9) 
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and the probability that all N bell measurements registered a successful result is 

„„ „ — („true , false\N 
PBell — \Pswap > P swap J 

We then have 



N N 2 
Ptrue = PBeU9 <* 



V false = p% eH {8ad+16d" + (1 - g N )a 2 ) 



These can be plugged into ( 3.12 ) and ( 3.13 ) to get the final communication rate. 
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FIG. 5. Comparison of Ekert protocol with regulated EPR source, one swap scheme, and two swap scheme. Fibers and 
detectors are taken for the 1.5/xm window. 

In Figure || we show a comparison between the Ekert protocol with an ideal entangled photon source, a one swap 
scheme, and a two swap scheme using a fiber optic channel at 1.5/xm. The swaps result in a longer cutoff distance 
which can lead to longer communication ranges. It should be noted however that at these distances the natural fiber 
loss is substantial and will lead to very slow communication rates. It is unclear whether swapping will lead to a 
practical form of quantum key distribution, but a single swap could be useful for very long distance QKD. 



V. DISCUSSION 



A standard quantum key distribution experiment involves three steps: raw quantum transmission, error correction, 
and privacy amplification. In the first two steps, Alice and Bob exchange a key which is partially secure. The purpose 
of the third step is to compress this partially secure key to a shorter key which is as secure as desired. The natural 
question to ask is, what is the relationship between the length of the final key and its security? This question has 
already been answered in previous work for the BB84 protocol with the restriction that Eve is only allowed to attack 
each bit individually. In this paper we provide a similar answer for the Ekert protocol. 

In summary, suppose that two parties wish to communicate using the Ekert protocol. They can then ensure that 
their final key is secure against general individual attacks by performing the following. After error correction, they 
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calculate the disturbance measure which is defined as 



n err + nu/2 

Tlrec 

where n rec is the number of bits in the error corrected string, n err is the number of error bits, and no is the number 
of dual-fire events in which more than one photon counter was triggered. They next calculate the parameter t, which 
is given by 

r = -log 2 Q + 2e-2e 2 ^ . 

Using the techniques of generalized privacy amplification discussed in || , they compress their key to a shorter key of 
length r given by 

where n is the number of bits exchanged during error correction and t and s are independent security parameters 
chosen by the two parties. The choice of these parameters depends on how much security is desired on the final key, 
which is quantified by an upper bound on Eve's mutual information. This bound is explicitly given by 

I E (K;GUZ) < 2~V + 2^7 In 2, 

which is exponentially small in s and t. 

Using the above results we compared the performance of BB84 and Ekert for both ideal and practical sources. 
We investigated fiber-optic as well as free-space key distribution scenarios. The Ekert protocol was shown to have 
significantly better performance at longer distance provided that the source can be placed midway between the two 
communicating parties. This opens up the possibility for communication lengths of up to 170km, although at low bit 
rates. The low bit rate is predominantly caused by the fiber losses. 

Finally, we analyzed a more complicated scheme based on entanglement swaps using only linear optical components, 
photon counters, and a clocked source of entangled photons. Entanglement swapping can allow for even longer distance 
secure communication, but at some point the natural loss of the fiber becomes so severe that the communication rate 
is prohibitively slow. 
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APPENDIX A: INFORMATION BOUNDS ON EAVESDROPPING. 



In this appendix we show how to bound Eve's expected information Ie(K; GU Z) by the average collision probability 

( Pc (x\z)) z = Y,P(z)Pc{X\Z = z), (Al) 

Z 

where 

P c {X\Z = z) = Y J P 2 {Az). (A2) 

X 

Let U and Z be arbitrary, possibly correlated, random variables over alphabets U and Z respectively. Let | • | denote 
the cardinality of a given set. Let t > be a security parameter chosen by Alice and Bob and define set A as 

A=^(u,z)e(U,Z):p(u\z)>^Y (A3) 

Defining A c as the complement of set A we have 
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P(A C ) = £ p(u,z) 

(u,z)£A a 

= Y p( u \ z )p( z ) 

S p[z) 

= 2-*. 

Thus with probability of at least 1 — 2 _t the combined string (U, Z) take a value in A. Then for another random 
variable X 



{p c (x\z = z)) z = J2p(z)J2p 2( . x M 



zez x 

/ \ 2 



Thus 



= J2p( z )Y1 I ^p{ u \ z )p{x\uz) \ 

> J2p( z )J2J2p 2 ( u \ z )p 2 (x\ uz ) 

zez x ueu 

= Y p( u ' z )p( u \ z )^2p 2 ( x \ uz ) 

z£Z,u&A x 

> p( u \ z )p( u ' z )^2p 2 ( x \ uz ) 

(z,«)eA x 

E P(u,z)P c (X\U = z,Z = z). 
1 1 (z.u)eA 



Y, p(u,z)P c (X\U = z,Z = z) < 2 t \U\(P c {X\Z = z)) z . (A4) 

(z,u)£A 

We can now use this result to bound H(K\GUZ) as follows: 
H{K\GUZ) = Y,P( U > Z )H(K\G, U = u,Z = z) 

= Y p{u,z)H(K\G,U = u,Z = z)+ Y p(u,z)H(K\G,U = u,Z = z) 

(u,z)eA (u,z)eA c 

> Y p{u,z)H(K\G,U = u,Z = z), 

using the positivity of the conditional entropy functions, and the fact that U and Z are independent of G. Plugging 
( [2.22 ) into the above inequality leads to 

H(K\GUZ)> Y P(u,z) (r- -^-p c {X\U = u,Z = z) 



(u,z)eA 



> (l-2- t )r-^2 t \U\{p c (X\Z = z)) z 

= (1 - 2~ f )r - 2 r+t+log 2 M+\og 2 { Pc (x\z=z))^ 



as follows from (A4). We can then set 

r = -\og 2 (p c {X\Z = z)) z -t-K-s, (A5) 
where k — log 2 \14\ is the number of bits in message U and s is another security parameter. This leads to the bound 
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H(K\GUZ)>(l-2-y-^. (A6) 



Eve's mutual information can now be bounded by 

I E (K; GUZ) = H(K) - H(K\GUZ) 



2~ s 



Plugging ( |2.18| ) into ( |Aq) leads directly to 

T = TIT — t — K — S, (A7) 

where r = — log 2 p c ■ 

APPENDIX B: SEPARATING COLLISION PROBABILITY INTO PHOTON NUMBER 

CONTRIBUTIONS 

We begin by first restating a theorem proven in the Appendix of [p5| which will play an important role in this and 
some of the following appendices. This theorem states that the expected collision probability can only increase in 
the presence of more detailed knowledge. Mathematically it is stated as follows: if the joint probability of signal i 
and measurement outcome I is split up into two measurements /' and V as p(i, I) = p(i, I 1 ) + p(i, Z" ) for all i then the 
average collision probability can only increase. Multiple applications of this theorem show that if a joint probability 
for all signals is broken up into more measurements this can only improve the average collision probability. 

We now define the projectors 

i 

Ef = ^2\x,i-x) a {x,i-x\ (Bl) 
x=a 

i 

Et = J2\y,i-y) b (y,i-y\, (B2) 
v=o 

which projects modes a and b onto the the subspace where the total photon number is i. It is clear from the above 
definition that 

oo oo 

£25? = (B3) 

Eve will generate a density matrix p a f, e which represents the combined state of Alice and Bob's signal and Eve's 
measurement probe. We expanded p a b e as 

00 

Pabe = PabeEfE]. (B4) 

hj=0 

We now prove that if p a be is replaced by the density matrix 



1 

Pabe 



£ E£ Ej pabeE? Ej , (B5) 

i,j=0 



this has no effect on the measurements of Alice, Bob, or Eve. Note that p' abe is the same density matrix as p a i> e minus 
the off diagonal terms which couple states in different photon number spaces. 

To prove our claim let ip a and ipb be the measurement results of Alice and Bob. They could represent the reception 
of an x, y, u, or v polarized photon, or they could represent an ambiguous dual fire detection. We define F^ a and 
F^p b as the POM's corresponding to these different measurement results. All the POM's which Alice can perform are 
of the form 

00 

Fil> a = ^2 OL m n\m,n) + {m,n\ + f3 mn \m,n) x (m,n\, (B6) 

m,n— 
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where \m,n} + and |m,n) x represent number occupations in the x-y and u-v basis respectively. We can rewrite this 



as 



F ^a=^2 E i a mn \m,n) + (m,n\+ (3 mn \m,n) x (m,n\ 

i—0 m.n—0 



= Y E ? Y a mn\m,n)+(m,n\ + f3 mn \m,n) x (m,n\ 

i—0 rn+n=i 

= ^2 E i[ Y a mn \m,n) + (m,n\+p mn \m,n) x (m,n\ E% 

i—0 \m-\-n—i / 

oo 

= Y E i F i E i- 



i=0 



Similarly we can write 



F^ b =Y,E^E\. (B7) 



The joint probability that Alice measures result tp a , Bob measures ip b , and Eve finds her probe in state k is 

p(ip a ,ip b ,k) = Tr {p abe Fj, a Fj, b E k } , (B8) 
where E k is the projection onto state k of Eve's probe. This can be rewritten as 

p(Va, ih, k) = J2 Tl {pabeE?E b F^ a F^E k } 

i,3 

= Tr { PabeEtE) Y E a m E b n F^F b E a m E b n E k \ 

i,j K inn ) 

i,j 

= ^ Tr {E?E b p abe E?E b F?F b E k } 

i,3 

= ]T Tr {EtE b p ahe E a l E b F i ,F^ b E k ) 



1,3 



= Tv{p' abe F^ a E k }. 

Thus, both matrices result in the same joint probability. This means that the most general density matrix can be 
written in block diagonal form 



Pabe = Y E ^E b p abe E°;E b 



— 2-^1 ^abe i 

where the matrix p^P is a matrix over the entire hibert space of Eve's probe, and the subspace in which Alice receives 
i photons and bob receives j photons. 

We now show that Eve's optimal strategy will be to keep track of how many photons she is sending to Alice and 
Bob. We define \p k ) as the measurement basis over which Eve will measure her probe, and F^ as the positive operator 
measurement performed by Alice's detection unit. We then have, using the above expansion 



p(tp,Pk) = Tr{p ahe i^ \p k ) (p k \} 

ij 

= ^Tr{( Mfc |p^|M^}- 
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Eve can always construct a new state which will perform at least as well as the above and will allow her to keep track 
of how many photons she sent. Define the new density matrix 



Pa b e = J^p { :H (B9) 

ij 

where 

ft&=P%l®\ij) a (ij\, (BIO) 

and the term \ij)„ is the state of an auxiliary system which keeps track of the number of photons sent. This new 
state will not change the measurement outcome of Alice or Bob because tracing out over the auxiliary system leads 
to the original density matrix. We define the new measurement basis as 

\p [ r ] ) = IM ® \mn) a . (Bll) 

If Eve measures in this new basis we have 

MV^) = Tr{^r } \Pa b M mn) )F^ , (B12) 
and using the above definitions it is easy to show that 

(Pk nn) \Pabe\Vk nn )) = (Hk\Pab } e\Pk)5i m Sj n . (B13) 

Combining these two equations one gets 
Furthermore, 

p(V,/ifc)=£P^ji mn) )- (B15) 

mn 

The measurement jik has been split up into more detailed measurements whose probabilities add up to the original. 
As stated earlier this more detailed information can only lead to an increase in the average collision probability, thus 
the new probe and measurement basis must be at least as good as the old one. 



APPENDIX C: BOUND ON ONE PHOTON CONTRIBUTION FOR COLLISION PROBABILITY 

In this Appendix we put a bound on pi 11 * 1 which is defined as the contribution to the collision probability from 
signals in which Alice and Bob each receive one photon. We assume that Eve can store her probe coherently until until 
she learns all relevant information from public discussion. Her only restriction is that she must measure each probe 
independently During the public discussion, Eve will learn the measurement basis used by Alice and Bob. She will 
also learn which bits were received correctly, and which incorrectly from the error correction phase. This information 
can potentially refine her measurement by allowing her to split bits into groups which will receive different treatment. 
A different measurement basis will be used for each case. We will define this basis as 

|dfc) — bit received correctly in x-y basis 
\bk) — bit received correctly in u-v basis 
|cfe) — bit received incorrectly in x-y basis 
\dk) — bit received incorrectly in u-v basis 

Each signal sent has a probability pi^J of entering the reconciled (error corrected) key. The signal can enter the key 
as a correct transmission or an error which will happen with probability p^rV . 

We first assume that p^J is a pure state. There is no loss of generality in this because for any mixed state one can 
construct a pure state which is at least as good. We can show this by first expanding p^J in pure states 
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p&^E^XiM- 



(CI) 



If Eve uses the measurement basis \/ik) then 

p(ip,(j,k) =E°' iTr ^'" fe i ^ ^ ^} • 

Suppose now that instead of sending the mixed state Eve sends the pure state 



ibe 



(C2) 



(C3) 



where |i) are the eigenstates of an additional system which keeps track of which pure state was sent. One can define 
a new measurement basis 



It is easy to show that 



|/4) = W) ® |t). 



(C4) 



(C5) 



It is also clear that this new state does not change the measurement outcomes for Alice and Bob, because tracing out 
the additional system results in the same density matrix as before. Thus, the new state must be at least as good. 

Rather than using the more cumbersome occupation number notation, we will adopt a shorthand notation for the 
case where only one photon is sent to either Alice or Bob. We will use the eigenstates \xx), \yy), \xy), \yx) to denote 
the different polarization states. Starting with the most generic state \ip) a bei we expand it in the polarization basis as 



\ip) = \xx) (xx\ if}) + \yy) (yy\ ip) + \xy) (xy\ tp) + \yx) (yx\ ip) 
= \xx)\P xx ) + \yy)\P vv ) + \xy)\P xy ) + \yx)\P yx ), 



(C6) 
(C7) 



where the states \P s t) represent Eve's probe and are not necessarily normalized or orthogonal. It should be noted 
that the above state is not normalized to 1 but 



(Pxx \ Pxx) + (Pyy \ Pyy ) + (P X y\P X y) + (Py X \Py x )=Pll, (C8) 

where p u is the probability that Eve only sends one photon to Alice and Bob. Using the relationships 



one can rewrite (C6) as 



where 





In) =-^(1*) + 


\v)) 




(C9) 






\v)), 




(CIO) 


= \uu) 


\Puu) + \w)\P vv ) + 


uv)\P uv ) 


+ \vu)\P vu ), 


(Cll) 


Puu) 


= \ (l^xx) + \Pyy) 4 


- \P X y) + 


\Pyx)) 


(C12) 


Pvv) 


= 2 (\P XX ) + \Pyy) ~ 


\Pxy) ~ 


\Pyx)) 


(C13) 


Puv) 


= 2 (l-^*) — \Pyy) ~ 


- \Pxy) + 


\Pyx)) 


(C14) 




= \ (\P XX ) - \Pyy) 4 


- \P X y) - 


\Pyx))- 


(C15) 



We will introduce the notation 
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(afcl Pxa 



(C16) 



and use the same notation for all other projections. Without loss of generality we can assume that the projections 

ok 
st 



P s fe t are real. If these projection are complex numbers then we can always find a probe of higher dimensionality which 



has real projections and is at least as good, using the same trick of probability splits described in Appendix [B|. Take 
for example the projection P xx - We can rewrite this as 

p(x, o fc ) = \rc[P* x ] 2 + Jlm[P*J 2 . (C17) 
We expand |a*) and \P XX ) in the some orthogonal basis \v{) so that 



\Pcr 



^2,on\vi) 

i 



and define 



IP* 



i 



We can then define a new probe 



and two new measurements 



IP, 



,Re\ 



Tm\ 



(|o fc > ® Is) + K) ® |y)) 



(|Ofc) ® |a:) 



It is easy to show, using (C17), that the projections on this new probe are all real and that 

p{x,a k ) = p(x,a^ e ) + p(x,a k m ). 



(C18) 

(C19) 
(C20) 

(C21) 



This state must be at least as good for the aforementioned reason, so an optimal solution exists which has only real 
projections. We can now write all the relevant probabilities as 



1 2 

p{x, Ojfe) - - (PL) 


(C22) 


p(y,a k ) = \{P* y ) 2 


(C23) 


P{x,Ck) = \ (P xy ) 2 


(C24) 


P(V,Ck) = \ (Pyx) 2 ■ 


(C25) 



The probabilities in the u-v basis are obtained by replacing x and y with u and v and a and c with b and d respectively. 
These define all the probabilities which will factor into pi 11 ^ . 

We can now write the collision probability in terms of the above expressions 



(ii) = 1 y ( 
4„(iD ^ I 

iPrec k \ 



(p x \y + (p y %) 4 [ply + (pLY , (p x k v y + (p v k x y , (pLY + (PLY 



(P x k x f + (Py k y ) ( p LY + (PIT (p x %Y + (Py k x ) ( pk vY + (PLY 



(C26) 
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Using the Cauchy inequality discussed in j2^, Appendix] we can put an upper bound on the above expression of the 
form 



P 



< n) < 1 



1 



(Eft -Pxx^i 



(V P k P k Y 

\y -*k uu w ) 



2b (11) 



^2ki^xx) Sfe (Pxx) Sfe (Puu) +Sfc(^ro) 



xy yx ) 



(Sfe Put! Pi 



k \ 



*}2k{Pxy) + J2k(Pyx) J2k(P£v) +J2k(Pvu 



However we notice that 



= (p,t\ p, 



(C27) 



using the completeness of Eve's measurement basis. Thus our new bound on the collision probability is 



P, 



l n ><l- 



(Pxx I P\ 



mil 



(Puu\ Puui 



2Prec \ (P^^l Pxx) ~\~ (Pyy | Pyy) (Puu\ Puu) ~t~ (Puu| Pu 
(Pcyl Pyx) 



(Pry I Pry) 



(Pyal Pyx) 



(Puv j Puv) (Pvu\ Pvu) 



The relations in (C12)-(C15) can be used to replace the u-v terms with x-y terms. We also impose the symmetric 
eavesdropping conditions 



(Pyy \ Pyy) 



Pxy \ Pxy) — (Pyx \ Pyx I , 



(C28) 
(C29) 



which state that Eve must keep the number of x and y states balanced. If Eve does not maintain these conditions, 
she will be immediately detected because Alice and Bob will note an asymmetry in their measurements. It is also 
shown in p3] that these are not restrictions because any state which does not satisfy the above symmetry conditions 
can be replaced by one that does and which is at least as good. Taking into account all these conditions one sees that 
there are very few degrees of freedom left to optimize. They are (P xx \ Pxx), (Pry I Pxy), and the angles and <p}j.y. 
The probability that a signal will enter the reconciled key is 



p(n) 

free 



i 



({Pxx\ Pxx) + (Pyy I Py 



(Pry | Pxy) + (Pyx \ Pyx)) j 



(C30) 



and the probability that it will enter the sifted key as an error is given by 



1 



Prec a {(Pxx\ Pxx) + (Pyy \ Pyy) + (Puu | Puu) + (Pvv \ Put;)) • 



(C31) 



The above relations can be directly plugged into the definition of the disturbance to give 

(u) = (P.,1 Pxx) (1 - cospjg) + (P xy \ Pyx) (3 - cosyjg) 

4 ((Pxx I Pxx) + (Pxy\ Pyx)) 

The collision probability is then bounded by 

^ 3 (Pxx\ Pxx) COS 2 ifH + (Pry | Pyx) COS 2 if™ 
V\ } < — — — ; — — + 



4((^f ? a;a;| Pxx) {Pxy\ Pyx)^) 



{Pxx\ Pxx) (Pxy \ Pyx) 
2 ((-Pea;! Pxx) H~ Pyx)^) 



(l + cos^)(l + cos^) 



{Pxx | Pxx) (l + COSlfxx) + (Pry | Pyx) (1 + COS (p% y ) 



(l-cosyg»)(l-cosygg) 



(Pxx | Pxx) (1 - COSipH) + (P xy \ P yx ) (1 - COS^y) 



(C32) 



The right hand side of the above equation should be maximized subject to the constraint given in Equation C32. As 
shown in pq , the maximum is achieved when cos^™ = cosy>|^ = 1 — 2e n and (P xx \ Pxx) = (PxV\ Pxy) (1 — e il )/e 11 . 
The resulting bound on the collision probability is 



2G 



< ^ + 2e ( 11 )-2( e ( 11 )) 2 . (C33) 

The above equation indicates that for e^ 11 ) = 1/2 Eve can have complete knowledge over Alice's key. This can be 
accomplished by sending Alice one of a pair of maximally entangled photons and keeping the other, while sending 
Bob a third photon with completely random polarization. After the measurement basis is revealed, a measurement 
of the retained photon will tell the bit value of Alice's string. 



APPENDIX D: HIGHER ORDER NUMBER STATE CONTRIBUTIONS 



Higher number states are taken into account by setting w D sufficiently large so that Eve's optimal strategy is to 
only use single photon states. If Eve sends n photons to Alice or Bob, the probability that all n photons will be 
measured in the same basis is 2 x 2 _ ". If Eve sends i photons to Alice and j photons to Bob we have 

(Dl) 
(D2) 




which leads to 

ij 

Pd 



> —L-^ > 1. (D3 



As noted above a disturbance of 1/2 already implies that Eve can obtain the entire string. So setting wd to 1/2 
means that Eve can do at least as good by sending only one photon to Alice of Bob. Thus 

Pc<i + 2e-2e 2 . (D4) 
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